Novell Home

CVE-2011-2939

Common Vulnerabilities and Exposures

[Previous] [Index] [Next]

Upstream information

CVE-2011-2939 at MITRE

Description

Off-by-one error in the decode_xs function in Unicode/Unicode.xs in the Encode module before 2.44, as used in Perl before 5.15.6, might allow context-dependent attackers to cause a denial of service (memory corruption) via a crafted Unicode string, which triggers a heap-based buffer overflow.

NVD CVSS v2 Base Score: 5.1 (AV:N/AC:H/Au:N/C:P/I:P/A:P)

Novell/SUSE information

Novell Bugzilla entry: 728662

SUSE Security Advisories:

List of released packages

Product(s) Fixed package version(s) References
openSUSE 11.3
openSUSE 11.4
  • icedtea-web >= 1.1.4-0.2.1
  • icedtea-web-javadoc >= 1.1.4-0.2.1
openSUSE 11.3
  • perl-base-debuginfo >= 5.12.1-2.7.1
  • perl-base-debuginfo-32bit >= 5.12.1-2.7.1
  • perl-debuginfo >= 5.12.1-2.7.1
  • perl-debuginfo-32bit >= 5.12.1-2.7.1
  • perl-debugsource >= 5.12.1-2.7.1
openSUSE 11.3
  • perl >= 5.12.1-2.7.1
  • perl-32bit >= 5.12.1-2.7.1
  • perl-base >= 5.12.1-2.7.1
  • perl-base-32bit >= 5.12.1-2.7.1
  • perl-doc >= 5.12.1-2.7.1
openSUSE 11.4
  • perl >= 5.12.3-11.18.1
  • perl-32bit >= 5.12.3-11.18.1
  • perl-base >= 5.12.3-11.18.1
  • perl-base-32bit >= 5.12.3-11.18.1
  • perl-doc >= 5.12.3-11.18.1

© 2014 Novell